
Dhole Moments
Writings about information security, cryptography, software, and humanity, from a member of the furry fandom.
From the Furry Fandom…
Featured Furries
Can’t get enough of blog posts written by furries? This post aims to curate some of the other blogs written by furries that are worth sharing with my regular readers. Many (but not all) of these furry blogs are focused on technology in some way. Background Information Many years ago, I wrote a post titled…
Soa Talks (Latest Posts)
Cryptography Engineering Has An Intrinsic Duty of Care
To understand my point, I need to first explain three different cryptography attack papers / blog posts. I promise this won’t be boring. Three Little Disclosures Misuse-Prone Ciphers For All In a blog post titled Carelessness versus craftsmanship in cryptography, cryptography analyst and Queer in Cryptography emcee Opal Wright delves into the misuse-prone and side-channel-riddled…
Cryptographic Issues in Matrix’s Rust Library Vodozemac
If you’re reading this after Matrix’s blog post, make sure you read the addendum to this one. Two years ago, I glanced at Matrix’s Olm library and immediately found several side-channel vulnerabilities. After dragging their feet for 90 days, they ended up not bothering to fix any of it. The Matrix.org security team also failed…
Is End-to-End Encryption Optional For Large Groups?
One of the recent topics in Messaging App Discourse is whether it makes sense to prioritize End-to-End Encryption (E2EE) when searching for an alternative to Discord. Who’s Saying “No”? I’m going to quote 0xabad1dea here, because she is awesome and explains my “opposition” position better than anyone else: So You Want To Write An Open…